The digital landscape of state-sponsored espionage has undergone a fundamental shift toward the weaponization of human psychology, as evidenced by the persistent Chosen Brick campaign. Orchestrated by the Iranian Ministry of Intelligence and Security, this operation has systematically targeted high-profile dissidents, journalists, and activists who live in exile across various Western nations. Since the middle of 2025, the campaign has matured into a sophisticated infrastructure designed to dismantle the digital and physical safety of those who challenge the status quo. Unlike conventional threats that prioritize technical exploits, this mission thrives on the slow cultivation of trust and the deliberate manipulation of social interactions. It represents a broader trend where intelligence services utilize highly personalized malware, dubbed Heavygram, to bridge the gap between digital surveillance and real-world harassment. By focusing on specific individuals rather than large organizations, the operators maintain a low profile while achieving deep, invasive access into the private lives of their targets.
Strategic Deception: The Psychology of Social Engineering
A defining characteristic of this campaign is the extensive social engineering phase that precedes any technical attack, demonstrating a level of patience rarely seen in automated phishing. Operators invest weeks or even months in researching a target’s background, professional interests, and personal affiliations before initiating contact on encrypted platforms like WhatsApp or Telegram. These initial interactions are often masqueraded as technical support requests from the messaging platforms themselves or as messages from established professional acquaintances. By engaging in long-form conversations that appear entirely benign, the attackers successfully bypass the natural skepticism that often protects high-risk individuals from sudden digital intrusions. This rapport-building process is critical because it conditions the victim to expect and trust future file transfers, effectively turning a human relationship into a vector for malware delivery. The psychological investment ensures that the eventual payload is received within a context that discourages any immediate suspicion or scrutiny.
Establishing Trust: Posing as a Legitimate Interlocutor
The deception deepens as the attackers employ contextually relevant lures designed to trigger a sense of professional or personal urgency within the target. For instance, dissidents have received files disguised as medical MRI scans showing degenerative conditions, or installers for specialized software like RunwayML and Pictory. When the victim executes the file, the malware maintains the illusion of legitimacy by displaying a functional decoy, such as a real medical image or a convincing login page, while the spyware installs in the background. This dual-action mechanism ensures that the victim remains unaware of the infection, believing they have simply opened a legitimate document or application. By using files that the target expects to see, the operators minimize the chance of the victim reporting the interaction to security professionals. This reliance on human-centric intelligence gathering allows the Iranian actors to bypass automated defense systems that typically flag generic or mismatched file types.
Delivering the Payload: Contextual Lures and Malware Delivery
One of the most alarming tactics identified in this campaign is the deliberate redirection of victims toward their personal hardware when professional security measures interfere. If an initial attempt to infect a work computer fails or appears likely to trigger enterprise-level security alerts, the attackers explicitly guide the victim to open the file on a home laptop. This strategy exploits the “blind spot” where professional-grade monitoring and endpoint protection are typically absent, allowing the malware to operate without interference. By understanding a journalist’s or activist’s daily workflow, the attackers identify the moments when a target is most vulnerable and least protected by corporate defenses. This transition from a secure environment to an unmonitored personal device represents a sophisticated understanding of modern cybersecurity architecture. It highlights how state actors adapt their methods not just to technical barriers, but to the behavioral patterns and environmental shifts of their specific human targets.
Technical Infiltration: Evasion and Surveillance Tactics
The technical architecture of the Chosen Brick spyware, also known as Heavygram, is specifically engineered for comprehensive surveillance and long-term persistence on infected machines. Once the malware gains a foothold, it achieves persistence by modifying registry keys and creating its own exclusions within Microsoft Defender to avoid detection by standard antivirus scans. Its capabilities are extensive, ranging from listing all running processes to activating the device’s microphone for secret audio recording and capturing real-time screenshots of the user’s activity. This level of access allows the Iranian Ministry of Intelligence and Security to monitor every digital move the victim makes, effectively turning their own computer into a surveillance outpost. The malware is designed to be lightweight and modular, allowing attackers to deploy specific payloads depending on the information they seek to gather. This modularity ensures that the infection remains difficult to analyze, as the full suite of malicious tools is rarely deployed at once.
Advanced Surveillance: The Trojanized Messaging Stack
A particularly invasive technique documented in recent reports involves the systematic harvesting of encrypted communication data directly from the victim’s web browsers. The malware is capable of stealing session data for platforms like WhatsApp and Telegram, allowing the attackers to bypass end-to-end encryption by accessing the messages at the endpoint. In some instances, the spyware goes as far as killing the legitimate WhatsApp desktop process and replacing it with a trojanized version that monitors communications in real-time. This allows the user to continue using the application without noticing any change in functionality, while every sent and received message is simultaneously exfiltrated to the attackers. Furthermore, specific payloads have been observed dumping entire Outlook mailboxes, including all attachments, into password-protected archives for clandestine extraction. This total visibility into the victim’s personal and professional correspondence provides the Iranian state with a comprehensive map of the target’s network and activities.
Infrastructure Control: Utilizing Encrypted Bots for Extraction
To manage the massive influx of stolen data while maintaining operational security, the campaign utilizes unique Telegram bot IDs for every individual victim infected. This compartmentalization ensures that if a single infection is discovered and the associated command-and-control infrastructure is blocked, the rest of the victim network remains secure from discovery. This tactic prevents “cross-contamination” and makes it significantly harder for cybersecurity investigators to map the full scale of the Iranian operation across different regions. The use of legitimate messaging platforms for command-and-control traffic also helps the malware blend in with normal network activity, as many users regularly use Telegram for personal or work communication. This strategy reflects a high degree of operational maturity, as it prioritizes the longevity of the campaign over the speed of data collection. By isolating each victim, the operators can maintain their surveillance for years, slowly gathering intelligence that can eventually be used for more aggressive actions.
Mitigating the Threat: Lessons From the Spyware Response
Security experts recommended that individuals at risk should transition to hardware-based security keys and maintain strict device isolation to mitigate these persistent threats. The analysis of the Chosen Brick campaign highlighted that technical defenses alone were insufficient when the attack vector was a trusted human interaction. Organizations improved their protocols by educating staff on the dangers of moving professional communications to personal hardware where monitoring was absent. By documenting these tactics, intelligence agencies provided a roadmap for identifying future surveillance attempts before they escalated into physical violence. It was observed that the most resilient targets were those who treated unsolicited file transfers with extreme caution, regardless of the sender’s perceived identity. Moving forward, the integration of behavioral analysis and enhanced endpoint protection became the standard for protecting those vulnerable to transnational repression. These defensive strategies successfully reduced the impact of state-sponsored spyware by narrowing the window of opportunity for attackers to exploit personal blind spots.
